PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71047 Oracle CVE debrief

A vulnerability in Oracle Identity Manager allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to takeover. Oracle has released an advisory and NVD has analyzed the vulnerability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager. Defenders should assess their exposure and apply patches or mitigations as necessary. The vulnerability has a high CVSS score of 8.8, indicating a high severity. The CVE record and NVD analysis provide details on the vulnerability, its impacts, and affected versions.

Vendor
Oracle
Product
Identity Manager
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Defenders of Oracle Identity Manager instances, particularly those with network exposure, should assess their exposure and apply patches or mitigations as necessary. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager. The vulnerability has a high CVSS score of 8.8, indicating a high severity. Defenders should verify their instances and apply patches or mitigations as necessary to prevent potential takeover.

Why it matters

Defenders should care about CVE-2026-71047 because it allows low-privileged attackers to potentially take over Oracle Identity Manager instances, impacting confidentiality, integrity, and availability. Affected versions require verification and patching.

  • Potential takeover of Oracle Identity Manager instances
  • Compromise of confidentiality, integrity, and availability

Technical summary

The vulnerability in Oracle Identity Manager (component: Core) allows low-privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in takeover. Affected versions are 12.2.1.4.0 and 14.1.2.1.0. The vulnerability has a high CVSS score of 8.8, indicating a high severity. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability is easily exploitable and allows low-privileged attackers to compromise Oracle Identity Manager, potentially leading to takeover.

Defensive priority

High

Recommended defensive actions

  • Review and apply Oracle's security advisory
  • Assess exposure of Oracle Identity Manager instances
  • Verify version and apply patches if necessary
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD analysis provide details on the vulnerability, its impacts, and affected versions. The vulnerability is caused by a weakness in the Core component of Oracle Identity Manager. The CVE record was published on 2026-09-15T20:17:42.230Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle Identity Manager, potentially leading to takeover. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. The CV

Sources and references

Verified primary and authoritative sources

  • CVE-2026-71047 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-71047

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-71047 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71047

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.